Improper access control in OpenClaw - #VU132745
Published: May 29, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a local user to load memory-core artifacts from an unintended local location.
The vulnerability exists due to improper access control in package root resolution for memory-core artifact loading when resolving a local package root influenced by workspace state. A local user can influence package root selection to load memory-core artifacts from an unintended local location.
Only instances with the affected feature enabled and reachable are vulnerable, and practical impact depends on whether lower-trust input can reach that path.